New install of Nesos ? Required?

I have recieve the follow from the admins of deSec

"During the last 31 days, you performed a dynDNS update using an outdated HTTPS encryption method (TLSv1.2/DHE).

We are about to disable support for this connection method. Before we do so, we just wanted to let you know about the upcoming change. In case you experience connection issues after the change, we recommend updating your dynDNS client."

Im not sure if this message means I should simply update my client to make sure the IP is updated or if it means Im suppose to install new software.

The current software I am using is DynamicDnsUpdater.exe program called “Nesos - Dynamic Dns Updater” Version 1.2.0.37078 windows 7. (it is more of an appliance )

Please advise.

Am I suppose to install Nesos-ita enforce tls1.2 or 1.3 maybe ?

Update:

I’m kinda confused because it appears version 1.2 is pretty much the latest version. Can someone help me sort out my confusion?

Regards.

The message is about the software you use to update your DNS records. It connected to the deSEC servers with TLS version 1.2, which deSEC won’t support much longer. According to a message on the developer’s page, the latest version of the software, which is from six years ago, also supports TLS 1.3, so you should be good without an update. The protocol is negotiated between client and server on connection. If, contrary to the developer’s announcement, the software fails to work with TLS 1.3, the software will need to be updated or you will need to use a different software.

1 Like

No, I think the point of the message was not TLSv1.2 per se, but the DHE ciphers no longer being supported. TLSv1.2 remains supported (when used with the more secure ciphers).
See: Drop DHE TLS ciphers #1189 and feat(www): drop DHE TLS ciphers #1231

2 Likes

I stand corrected. Maybe it’s just time to retire Windows 7, but there is a chance that with the latest available update to the .net framework, the required cipher suites can be enabled. The developer may roll his eyes at you if you ask him for an update so that you can keep using Windows 7 though.

1 Like

Probably :wink:

I had a similar situation a few years back on an older macOS machine. I eventually used stunnel on a more modern LAN-host (OpenBSD VM) and channeled the requests through that to get more modern TLS.

I have no idea about .NET updates. But that may be worth a try at least. Might be less complicated to set up than stunnel?

1 Like

So Im an end user and I suppose the nice thing about this whole situation is that I have set it up and then forget it. I need to do nothing else just let it run. I say this because I really dont understand much about the tech of all of this.

I have re read the messages and realize that I have been confused, not that that changes much. But I thought 1.2 and 1.3 were the versions of the software Neso that I downloaded. It is of course not. It is the versions of some sort of protocal used to communicate with the dedyn.io (from what I can gather) that the software uses.

Of course this confusion seems to be added to by the fact that there seem to be some sort of other thing called DHE cipher.

However having said all of that, you seem to indicate that you think my current software will continue to work.If i understand your points. I do wonder then, why I got the email message ?

Thank you for your comments.

Please advise

Windows 7.

Well this is as I mentioned kind of an appliance. That means, its not really upgradable. For example a security video server custom designed to store videos from security cameras. It does not (need) to upgraded as thats all it does. And would cost 1,000’s to do so just for one software package.

Thank you.

Also IF i need to update with new software, what can I use?

Regards.

TLS is the protocol used e.g. by HTTPS connections. It encrypts traffic between your client and the server (https://update.dedyn.io in this case). Without that encryption someone could learn your deSEC credentials and hijack the connections to your appliance.

There are versions of TLS (e.g. TLSv1.2, TLSv1.3) and the protocol can use various ciphers internally. Some of those, such as DHE, are no longer secure, so they should not be used anymore.

In most cases client software relies on services of the operating system for these implementation details. However a very old OS does not know that some of these ciphers are now insecure.

So your options are:

  1. Update your OS. (Apparently not possible in your case.)
  2. Update or reconfigure the services of the OS that provide the details for TLS. (Maybe a .NET upgrade would help, but I’m not a Windows expert. Maybe Windows 7 has some other configuration setting to disable the DHE ciphers?)
  3. Use a solution such as stunnel described above to provide modern TLS externally. (Requires a certain amount of technical knowledge, sorry.)

In any case, if the reason for getting a DynDNS hostname for your public Internet address is access to your appliance from the Internet, then that old Windows 7 probably poses a security risk even setting aside the TLS issues you are seeing.

So yes, with some effort you can put a bandaid on the TLS issue. But ultimately you need to think about a major upgrade.

Most DynDNS clients rely on the OS (in layman’s terms, for more technical people: OpenSSL, LibreSSL, .NET?, …) to provide basic services such as TLS. So I doubt changing the DynDNS client software will help. But maybe someone else has a suggestion?

I don’t speak for deSEC e.V. but I fully understand their decision to cut off <0.01% of its users to make the service more secure. Bad luck that it happens to affect you. But that’s what you can expect when using outdated software. Be happy that they sent you a personal notification about the change, probably saving you quite a bit of debugging effort and head-scratching.

1 Like

It’s not so much a matter of disabling DHE, as that will be done on the server side, so DHE won’t be used even if the client continues to offer it. The client probably doesn’t offer the more secure cipher suites, and it may be possible to get those by using the latest available update of the .NET framework for Windows 7. Then you may still need to enable additional cipher suites with the free “IIS Crypto” tool. It is also a possibility that the author of the dynamic DNS updater you use needs to make some changes and release new binaries.

I have used the external TLS “reverse proxy” method to make an ancient piece of software on Windows XP compliant with modern connection protocol requirements, so I can vouch for the feasibility of this approach. Unfortunately it is quite technical.

1 Like

You may be able to simply “move” the DynDNS updater functionality from your old appliance to some other, more modern system. Many routers can handle DynDNS or you could set it up on a Raspberry Pi or some such.

Caveat: This approach only works if the updating system has the same internet-facing IP address as that appliance, e.g. if you still get an IPv4 address from your internet provider and NAT your local network behind it. This used to be the common setup for homes and small businesses. However, these days internet providers move towards IPv6, which would probably mean that your appliance has a different address than the separate updating device. That would complicate things quite a bit.

Thank you for your many helpfull responses. I find that routers seldom have the settings that one wants.

This link shows the list of dns settings for dyndns. Sadly dedyn.io is not there.

https://imgur.com/a/k08k7et

Does any one know which ones are free and which ones are not chinese or usa. We cant use usa products as we are canadian and are mandated to no use usa products when others are available. Thanks. (we use to use dyndns.org untill they started charging years ago.) I had used Duckdns but something happened to them and they were inconsistent.

If there is an option to supply a custom update URL, you can use that. The only real requirement is that you make a secure connection to the deSEC web server and request a single URL with your access token and the domain name to be updated. Even the IP address in the URL is optional if you connect from that IP address. See the documentation.

1 Like

Thanks I will take a look.